Analyze policy change impact
Before you begin
-
Enable the Policy Change Impact Analyzer toggle under Insights & Reports > Settings.
-
To view historical impacted connection counts, enable Security Analytics and Logging.
-
Policy Change Impact Analyzer currently supports Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense devices.
Procedure
Step 1 | In the left pane, click Insights & Reports > Policy Change Impact Analyzer. The Policy Change Impact Analyzer page displays an Impact Analysis summary, including the number of identified impacts. The device list displays:
| ||
Step 2 | Select one or more devices, and then click Run Impact Analyzer. You can select up to 10 devices for analysis. The analyzer evaluates the pending policy changes for the selected devices. | ||
Step 3 | Monitor the analysis in the device list. Use the search field to search by device name, analysis result, or job status. | ||
Step 4 | Click a device row to open the details pane. The pane displays the device status and may include these actions:
| ||
Step 5 | Click the device name to open the analysis report. The analysis details page displays the overall impact assessment for the selected device. | ||
Step 6 | Review the Analysis Result, Rule Change Summary, Impacted Traffic Segments, Impacted Connections, and Inferred Impact. | ||
Step 7 | If the analysis is incomplete, failed, out of date, or indeterminate, review the policy manually before deployment and rerun the analysis as needed.
|
The Policy Change Impact Analyzer displays the potential impact of pending access control policy changes, including changed rules, impacted traffic segments, historical connections, inferred impact, and rule change summaries.